Decryption exemption required to access DNF updates
11722
Created On 01/25/23 16:41 PM - Last Modified 06/15/23 04:36 AM
Symptom
Connection for dnf updates do not work over ssl decryption environment
Environment
Firewall configured with ssl decryption and the end Centos/RHEL host making a 'dnf' connection for updates.
DNF stands for Dandified YUM and is basically an improved version of the YUM package manager. It offers more features while installing, updating, or removing software packages in a RedHat based Linux system.
Cause
- As per the requirement of dnf connection by Redhat, connection to s list of URLs have to be exempted from ssl decryption to ensure a successful connection with Redhat server.
- This condition form Redhat has been listed in detail in this discussion
Resolution
The following URLs are required to be exempted from SSL decryption :
subscription.rhsm.redhat.com
subscription.rhn.redhat.com and
cdn.redhat.com
Additional Information
How to access Red Hat Subscription Manager (RHSM) through a firewall or proxy
https://access.redhat.com/solutions/65300